CVE-2016-6415

HIGH KEV

Cisco IKE Information Disclosure

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2016-6415 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 19, 2023. EIP tracks 4 public exploits from researchers including nixawk, 3ndG4me, Nixawk, including a Metasploit module auxiliary/scanner/ike/cisco_ike_benigncertain.

AI-analyzed exploit summary This exploit targets CVE-2016-6415, a vulnerability in the Netgear WNDAP360 firmware. It sends a crafted payload to trigger a buffer overflow, potentially leading to remote code execution.

Description

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

Exploits (4)

exploitdb WORKING POC
by nixawk · pythonremotehardware
https://www.exploit-db.com/exploits/43383

This exploit targets CVE-2016-6415, a vulnerability in the Netgear WNDAP360 firmware. It sends a crafted payload to trigger a buffer overflow, potentially leading to remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Netgear WNDAP360 firmware
No auth needed
Prerequisites: Network access to the vulnerable device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 11 stars
by 3ndG4me · infoleak
https://github.com/3ndG4me/CVE-2016-6415-BenignCertain-Monitor

This repository contains a functional exploit for CVE-2016-6415, a memory leak vulnerability in Cisco IOS/IOS XE. The exploit sends a crafted IKEv1 packet to leak memory contents, which are then processed to extract ASCII strings and store them in a SQLite database for analysis.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Cisco IOS/IOS XE (IKEv1 implementation)
No auth needed
Prerequisites: Network access to the vulnerable Cisco device · UDP port 500 (IKE) reachable
devstral-2 · analyzed Feb 18, 2026 Full analysis →
vulncheck_xdb WORKING POC
infoleak
https://github.com/VirtueSecurity/benigncertain-monitor

This repository contains a Dockerized Python script that leverages the NSA BENIGNCERTAIN exploit to continuously poll a vulnerable Cisco PIX device, extract ASCII strings from memory, and store them in a SQLite database for analysis. The script automates the process of identifying potential passwords and sensitive information over time.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Cisco PIX (CVE-2016-6415)
No auth needed
Prerequisites: Docker · Python 3.7 · NSA BENIGNCERTAIN exploit binary ('bc-id')
devstral-2 · analyzed Feb 25, 2026 Full analysis →
metasploit WORKING POC
by Nixawk · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/ike/cisco_ike_benigncertain.rb

This Metasploit module exploits CVE-2016-6415, an IKEv1 information disclosure vulnerability in Cisco IOS, IOS XE, and IOS XR. It sends a crafted ISAKMP packet to leak memory contents from the target device.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Cisco IOS, IOS XE, and IOS XR with IKEv1 enabled
No auth needed
Prerequisites: Target device configured to accept IKEv1 security negotiation requests · Network access to UDP port 500
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036841
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93003

Scores

CVSS v3 7.5
EPSS 0.8769
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact partial

Details

CISA KEV 2023-05-19
VulnCheck KEV 2016-09-28
InTheWild.io 2023-05-19
ENISA EUVD EUVD-2016-7338
CWE
CWE-200
Status published
Products (3)
cisco/ios 12.2 - 12.4
cisco/ios_xe < 3.18s
cisco/ios_xr 4.3.0 - 4.3.4
Published Sep 19, 2016
KEV Added May 19, 2023
Tracked Since Feb 18, 2026